Key Takeaways
- Anubis added Coca-Cola’s Fairlife to its leak site and claimed it encrypted Nutanix systems and stole 1 TB of internal data
- The July 2026 incident forced Fairlife to halt U.S. production while investigations continued
- The attack highlights broader ransomware pressure on food and beverage OT networks, which analysts say face rising risk
Coca-Cola’s Fairlife dairy subsidiary is facing mounting pressure after the Anubis ransomware group publicly claimed responsibility for the July 2026 cyberattack that disrupted its U.S. operations. The group listed Fairlife on its dark web leak site and asserted it exfiltrated roughly 1 TB of corporate data, although independent validation of that figure is still pending. The claims surfaced only days after Coca-Cola acknowledged the attack and confirmed that Fairlife production in the United States had been suspended.
Fairlife operates highly automated food manufacturing facilities, a sector that has been under growing strain from ransomware groups for several years. According to the company’s initial disclosure on July 16, attackers gained unauthorized access to a segment of Fairlife’s systems, including production-related environments, which prompted activation of incident response and business continuity procedures. Coca-Cola noted that product quality and safety were not affected and that Canadian operations were continuing normally.
Anubis escalated the incident by posting Fairlife to its leak site and asserting that it encrypted Nutanix infrastructure within the dairy unit. The group also accused the company of reporting the incident too quickly rather than following instructions allegedly left on the network. Claims of a full encryption of Nutanix systems fit the group’s pattern of targeting virtualized and hybrid environments, although the precise extent of the damage remains unverified. BleepingComputer indicated it could not confirm the claims about the 1 TB of data or the scope of encryption. Coca-Cola declined to comment when approached.
The timing and tactics align with Anubis’s broader approach. The group surfaced in December 2024 as a ransomware-as-a-service model, branching out across multiple industries. While data theft combined with file encryption has become a near standard playbook across many ransomware operations, Anubis bolstered its impact last year by introducing a data wiper designed to eliminate recovery paths. That addition raised concern inside industrial security circles, as destructive functionality often compounds downtime and increases the complexity of response.
This event at Fairlife also mirrors a wider pattern of ransomware pressures on the food and beverage sector, driven partly by the industry's dependence on tightly coupled supply chains and automated plants. The European Union Agency for Cybersecurity found that ransomware accounted for 54% of major cyber incidents impacting critical sectors, including food and beverage, between mid-2021 and mid-2022, a finding published in the ENISA Threat Landscape 2022. The Cybersecurity and Infrastructure Security Agency and the FBI cautioned in 2021 that ransomware activity against food and agriculture was accelerating, with potential for supply chain disruption.
Industrial control systems inside dairy and beverage plants tend to follow architectures that were originally isolated. Over time, connectivity expanded to support automation, monitoring, and remote management, creating new attack surfaces. The National Institute of Standards and Technology has repeatedly highlighted the risks to industrial control systems and operational technology, recommending segmented network designs and robust backup strategies in its guidance, including the widely used NIST SP 800-82. The broader NIST Cybersecurity Framework is also commonly applied in these environments as organizations work to identify, protect, detect, respond, and recover.
Gartner projected that by 2025, 30% of critical infrastructure organizations will experience a security incident that impacts their operational technology environments. That is up sharply from less than 10% in 2021, according to the Gartner forecast. Although projections like that tend to be conservative, they suggest that ransomware will continue to challenge industrial operators for years.
During operational technology incident response, firms such as Dragos and Mandiant typically focus on containment, forensic analysis, restoration of control systems, and eradication of persistent access mechanisms. While neither has been publicly connected to the Fairlife investigation, manufacturers that rely heavily on automated production lines face extended downtime during each stage of this recovery process.
Groups like Anubis, along with numerous other ransomware actors, are tracked by independent monitoring services and threat intelligence platforms. Ransomware.live is one example that catalogs claimed victims, giving researchers and affected industries another layer of perspective at a time when transparency is often limited during investigations.
Although Coca-Cola has not commented on the specifics of the Anubis posting, the situation continues to evolve. The threat of public exposure of allegedly stolen data typically adds urgency and may influence how companies approach negotiation strategy, dictating whether organizations prioritize rapid recovery, emphasize investigation first, or wait for verification of the threat actor’s claims.
The Fairlife incident underscores the increasing entanglement of operational technology risk, ransomware economics, and supply chain stability. Food and beverage companies have become attractive targets partly because production stoppages carry immediate consequences. Stronger architectural protections, clearer incident response playbooks, and wider adoption of available cybersecurity guidance remain necessary as the industry navigates escalating threats.
⬇️